Threat Advisory

Req Flaw Enables Unbounded Archive/Compression Extraction

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in req package, which could allow an attacker to exploit unbounded archive/compression extraction and multipart form-data header injection via unescaped.

CVE-2026-49755 (CVSS 7.5 — High): The req package is vulnerable to unbounded archive/compression extraction triggered by response content-type, allowing an attacker with network access capability to exploit this vulnerability.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in req package, which could allow an attacker to exploit unbounded archive/compression extraction and multipart form-data header injection via unescaped.

CVE-2026-49755 (CVSS 7.5 — High): The req package is vulnerable to unbounded archive/compression extraction triggered by response content-type, allowing an attacker with network access capability to exploit this vulnerability.[emaillocker id="1283"]

CVE-2026-49756: The req package is vulnerable to multipart form-data header injection via unescaped, which could allow an attacker with network access capability to inject malicious data. These vulnerabilities collectively present a moderate risk to administrators who have not applied updates. Administrators should review their exposure and apply patches as soon as possible. These vulnerabilities collectively present a moderate risk to administrators who have not applied updates.

These vulnerabilities collectively present a moderate risk to administrators who have not applied updates.

RECOMMENDATION:

We recommend you to update req to version 0.6.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu